跳到主内容

Casdoor vs. alternatives

People usually find Casdoor while evaluating an identity provider against one or two others. This page gives the short version; each linked page goes into detail and says plainly when the other product is the better choice.

Compared withRead this if you…
Keycloakwant a lighter, UI-first server than a Java stack, or are planning to migrate off Keycloak
Authentikare choosing a self-hosted IdP for a homelab or a small team
Auth0want to stop paying per monthly active user, or need to self-host
Logtoare building a SaaS product or an AI agent and want modern OIDC with a good developer experience

At a glance​

The table describes each project as of 2026. Products change quickly; check the other project's documentation before making a decision.

CasdoorKeycloakAuthentikAuth0Logto
Backend languageGoJava (Quarkus)Python and GoClosed sourceTypeScript (Node.js)
LicenseApache-2.0Apache-2.0MIT core, paid enterprise featuresProprietary SaaSMPL-2.0
Self-hostingYesYesYesNo (private cloud on enterprise plans)Yes
DatabasesMySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, TiDB, CockroachDBPostgreSQL, MySQL, MariaDB, SQL Server, OraclePostgreSQLManagedPostgreSQL
OAuth 2.0 / OIDCYesYesYesYesYes
SAMLIdP and SPIdP and SPIdP and SPIdP and SPIdP and SP
CASBuilt inVia extensionNoNoNo
LDAP serverBuilt inNo (federates to LDAP)Via outpostNoNo
RADIUS serverBuilt inNoVia outpostNoNo
MCP server and OAuth 2.1 for MCPBuilt inNo built-in MCP serverNo built-in MCP serverSeparate add-on productsOAuth 2.1 for MCP servers
Permission modelCasbin (ACL, RBAC, ABAC)Authorization Services (UMA)Policies and bindingsRBAC, plus a separate FGA productRBAC
Payments and subscriptionsBuilt inNoNoNoNo

What is specific to Casdoor​

  • One Go binary and a React UI. There is no JVM and no separate worker or cache process to operate; the only dependency is a SQL database.
  • Everything is configured in the web UI. Sign-in pages, sign-up fields, providers, and themes are edited in the admin console, not in template files. See UI customization.
  • Built for AI agents. Casdoor exposes its own management API as an MCP server and acts as an OAuth 2.1 authorization server for third-party MCP servers, including Dynamic Client Registration, PKCE, and resource indicators.
  • Wide protocol coverage. OAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS, SCIM, WebAuthn, and Kerberos are served by the same process.
  • Many sign-in providers. More than 70 OAuth providers are built in, including WeChat, DingTalk, Lark, and Alipay alongside Google, GitHub, and Microsoft.
  • Migration tools. Syncers import users from Keycloak, Okta, Azure AD, Active Directory, Google Workspace, or any SQL database, and keep them in sync during a gradual cutover.

When Casdoor is not the best fit​

  • You need a vendor to run identity for you with a contractual SLA and you have no interest in self-hosting. A managed service such as Auth0 removes that work. Casdoor also has a hosted offering if you want the product without the operations.
  • Your organization already has deep Keycloak expertise, custom SPIs, and Red Hat support. Staying is reasonable.
  • You need relationship-based authorization at very large scale, in the style of Google Zanzibar. Casdoor's permissions are built on Casbin, which runs in-process; a dedicated Zanzibar-style service may fit better.

Try it​

The fastest way to compare is to run Casdoor next to what you have:

docker run -p 8000:8000 casbin/casdoor-all-in-one

Then open http://localhost:8000 and sign in with admin / 123. See Try with Docker for details, or use the online demo.